I noticed a three-year-old thread about the verification email not getting delivered to Gmail, but decided to start a new thread since my issues is on Outlook 365. Nevertheless, I suspect the reason is the same. My email address is hosted on Microsoft 365 and I also happen to be the administrator, so I was able to do a full trace. The DMARC verification is failing. It appears Hubitat is using the Amazon SES DKIM keys to sign their emails, instead of generating their own DKIM keys. Hubitat should migrate to “Bring your own DKIM” or EasyDKIM to solve this problem. I’d be happy to send you the full email message headers via secure channel if you like.
Note, the reason this problem is only rarely reported is that it isn’t a problem unless the recipient is using email forwarding. For emails sent directly, the DKIM passes. However, since a certain percentage of users can be expected to use email forwarding, this should be fixed, and the fix is trivial. The fix doesn’t impact non-forwarded emails, and improves security.
Summary: The verification code email from Hubitat was sent to quarrantine without ever reaching the user’s inbox. The reason: suspected phishing.
Here is an excerpt from the message headers with the DMARC FAIL message:
ARC-Authentication-Results: i=2; ``mx.microsoft.com`` 1; spf=pass (sender ip is
54.149.36.10) ``smtp.rcpttodomain=``*************
smtp.mailfrom=mx1.mailhop.org``; dmarc=fail (p=quarantine sp=quarantine
pct=100) action=quarantine ``header.from=hubitat.com``; dkim=pass (signature was
verified) ``header.d=amazonses.com``; arc=pass (0 oda=0 ltdi=0 93)
Authentication-Results: spf=pass (sender IP is 54.149.36.10)
smtp.mailfrom=mx1.mailhop.org``; dkim=pass (signature was verified)
header.d=amazonses.com``;dmarc=fail action=quarantine
header.from=hubitat.com``;compauth=fail reason=000
Subject: My Hubitat Verification Code
MIME-Version: 1.0
My Hubitat:
Platform Version: 2.5.0.159
Hardware Version: C-8 Pro